iRhythm: Hackers Stole Patient Heart Data and Sent a Ransom Note
iRhythm Holdings, a digital health company that makes wearable cardiac monitoring patches, has disclosed a data breach after attackers broke into third-party-hosted business applications and made off with patient personal and health information. According to a filing with the U.S. Securities and Exchange Commission, the company discovered the intrusion on June 15 — one day after receiving a ransom demand from the attackers, who had first made contact on June 9 threatening to publish the stolen data online. iRhythm has not attributed the attack to a specific threat actor or extortion group.
The scale of the potential exposure is significant. iRhythm's cardiac monitoring service has processed data from over 12 million patients, representing more than 2 billion hours of heartbeat recordings. The company has not confirmed exactly how many patients are affected or precisely what data was taken, but the attackers claim it includes sensitive proprietary and patient information.
iRhythm says external cybersecurity experts are now involved and its incident response plan has been activated.
What you should do: If you have ever used an iRhythm cardiac monitoring device, watch for a notification letter from the company. Be alert to phishing attempts (scam messages designed to look like official communications) using your health information as bait — attackers who hold medical data often use it to make follow-up scams appear more convincing. Do not respond to any unsolicited contact claiming to be from iRhythm until you have verified it through their official website.
Sources

